Problem: "Hermes" collides with Nous Researchs unrelated product; unclear identity for the resident agent. Change: Rename the live service identity across 39 files: - cmd/hermes/ → cmd/nomos/ (binary, env vars NOMOS_*) - internal/config/ server.go (NomosAgentSlug, nomosAgentID) - compose/hermes/ → compose/nomos/ (Dockerfile, service name) - hermes/ → nomos/ (SOUL.md, config.yaml, skills/) - .agents/HERMES.md → NOMOS.md (persona) - tools/setup-hermes-soul.sh → setup-nomos-soul.sh - seeds/inventory.yaml (agent:hermes → agent:nomos) - migrations/014_rename_agent_hermes_to_nomos.up.sql - Caddy vhost hermes.hubris.network → nomos.hubris.network - All referencing docs, scripts, ADR notes History preserved: archive/, plans/done/, ADRs not rewritten. Matrix @hermes notifier account and Legacy bin/hermes on LXC 129 intentionally untouched (out of scope). Risk: N0 is identity-only rename; zero behavioral changes. Verification: go build ./... passes; docker compose --profile full resolves nomos service; grep -ri hermes (excluding archive/plans) returns only intentional refs (LLM model name, Matrix user).
Architecture Decision Records
MADR-style records for Oikos. One decision per file, numbered, never edited after acceptance — superseding decisions get a new ADR that links back. Statuses: proposed | accepted | superseded-by-NNNN.
| ADR | Title |
|---|---|
| 0001 | Go with single-binary role packaging |
| 0002 | PostgreSQL + TimescaleDB as the only datastore |
| 0003 | DB-native ontology with YAML seed manifests |
| 0004 | Contract-first OpenAPI API |
| 0005 | UUIDv7 + slug entity identity |
| 0006 | Learning is proposal-only (no self-authorization) |
| 0007 | Threat model and trust zones |
| 0008 | Forward-only migrations |
| 0009 | SSE over WebSocket for the event stream |
| 0010 | Infisical secrets with SOPS DR fallback |